Oracle Linux 10: Tomcat Vulnerabilities Addressed in ELSA-2025

Oracle Linux 10: Tomcat Vulnerabilities Addressed in ELSA-2025

First seen 12 Dec 2025, 12:53 UTC Linuxsecurity 18.3

Article Content

Browse articles
ThreatCluster

Oracle has released an important update for Oracle Linux 10 addressing multiple vulnerabilities in Tomcat. The update resolves issues including directory traversal with possible remote code execution (CVE-2025-55752), rule bypass in the Rewrite Valve (CVE-2025-31651), and a denial of service (CVE-2025-61795). Affected versions include tomcat9-9.0.87-8.el10_1.1 and related packages.